Am 18.06.26 um 16:42 schrieb William Herrin:
I'm almost never looking for a stateful packet inspector that isn't
doing NAT. Stateful gives it most of the same drawbacks of NAT
without the benefit of making my internal network inaddressible from
outside. But YMMV: a lot of folks don't have the comfort level with
stateless packet filters that I do, and SPIs do offer some additional
protection to hosts intended to be reached from the Internet.
If you really want, you can combine SPI firewalling with NAT66 (1:1
matching if you want).
For me, NAT and the aspect that the machines are not addressable from
the outside is a large disadvantage.
I do whatever I can with IPv6.
--
Gruß
Marco
Junk-Mail bitte an [email protected]
_______________________________________________
NANOG mailing list
https://lists.nanog.org/archives/list/[email protected]/message/MDZP77OG5ZDCV6TWIAIXNCUZYDDHYYIF/